Repository navigation
Releases: zeroscience/WaSAP
Releases · zeroscience/WaSAP
Release list
WaSAP 2.5.1
SAP-specific scan checks for Burp Suite, built on the Montoya API.
Three checks registered with Burp Scanner:
- Passive (PER_REQUEST): SAP fingerprints, NetWeaver/proprietary header disclosure, SAP session cookie flag checks, ABAP/J2EE verbose errors.
- Active per host (PER_HOST): 58-entry SAP endpoint catalog plus content/version-verified CVE probes (CVE-2025-31324 Visual Composer, also flagging the chained CVE-2025-42999; CVE-2022-22536 ICMAD; CVE-2020-6287 RECON; CVE-2020-6207 Solution Manager EEM; CVE-2017-12637 AS Java Scheduler traversal; catalog tags CVE-2020-6308 LMXML and CVE-2010-5326 Invoker) and /sap/public/info system-info extraction.
- Active per insertion point (PER_INSERTION_POINT): SAP-specific parameter checks only.
Findings are raised as standard Burp audit issues and require SAP corroboration before being reported, to avoid false positives on non-SAP hosts. Requires Burp Suite with the Montoya API. See CHANGELOG.md.
Build from source: ./gradlew jar